CVE-2018-6559: Infoleak
Last updated 25 August 2025
Other sources
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.13-1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6559?
CVE-2018-6559 has a medium severity rating as it allows local users to access file names they should not normally see.
How do I fix CVE-2018-6559?
To fix CVE-2018-6559, update the Linux kernel to versions 5.10.223-1, 5.10.226-1, 6.1.119-1, 6.1.123-1, 6.12.10-1, or 6.12.11-1.
Which Ubuntu versions are affected by CVE-2018-6559?
CVE-2018-6559 affects Ubuntu 16.04 LTS, 18.04 LTS, and 18.10.
What is the impact of CVE-2018-6559?
The impact of CVE-2018-6559 is that local users can gain unauthorized access to sensitive file names.
Is CVE-2018-6559 exploitable remotely?
CVE-2018-6559 is not remotely exploitable as it requires local user access to exploit the vulnerability.